USN-4053-1
Dashboard / Vulnerabilities / USN-4053-1
USN-4053-1
Summary: gvfs vulnerabilities
Details: It was discovered that GVfs incorrectly handled the admin backend. Files created or moved by the admin backend could end up with the wrong ownership information, contrary to expectations. This issue only affected Ubuntu 18.04 LTS, Ubuntu 18.10, and Ubuntu 19.04. (CVE-2019-12447, CVE-2019-12448, CVE-2019-12449) It was discovered that GVfs incorrectly handled authentication on its private D-Bus socket. A local attacker could possibly connect to this socket and issue D-Bus calls. (CVE-2019-12795)
References: https://ubuntu.com/security/notices/USN-4053-1, https://ubuntu.com/security/CVE-2019-12447, https://ubuntu.com/security/CVE-2019-12448, https://ubuntu.com/security/CVE-2019-12449, https://ubuntu.com/security/CVE-2019-12795
Affected packages
Package
Name: gvfs
Purl: pkg:deb/ubuntu/[email protected]~16.04.3?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
